OESA-2022-1966
Dashboard / Vulnerabilities / OESA-2022-1966
OESA-2022-1966
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.(CVE-2022-40307) A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for the Empia 28xx based TV cards. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.(CVE-2022-3239)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1966, https://nvd.nist.gov/vuln/detail/CVE-2022-40307, https://nvd.nist.gov/vuln/detail/CVE-2022-3239
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
